SonicWall experienced a significant security incident in early October 2025, resulting in the unauthorized access of firewall configuration backup files for all customers utilizing the MySonicWall cloud backup service. The breach exposed sensitive configuration data, including device settings, encrypted credentials, VPN configurations, private keys, and administrator information. Although the credentials and secrets were protected with AES-256 encryption, the exposure of this data raised substantial concerns about the potential for further exploitation, especially in cases where weak or reused passwords were present. Forensic analysis conducted by SonicWall in collaboration with Mandiant confirmed that 100% of cloud backup customers were affected, making this a global event with far-reaching implications for network security.
Following the breach, security researchers, including those at Huntress, observed a marked increase in SonicWall SSLVPN account compromises starting on October 4, 2025. Over 100 accounts across 16 customer environments were breached, with attackers using valid credentials rather than brute-force methods. The malicious activity was traced to a single IP address (202.155.8[.]73), and attackers were seen rapidly authenticating, conducting network scans, and attempting lateral movement within affected environments. In some cases, attackers disconnected quickly, but in others, they pursued deeper access by targeting local Windows accounts.
Evidence suggests that the Akira ransomware group may be leveraging both the stolen credentials and known SSLVPN vulnerabilities to facilitate these intrusions. While Huntress did not find direct evidence linking the observed SSLVPN compromises to the configuration file breach, the timing and nature of the attacks have raised concerns about a possible connection. The exposed configuration files, even though encrypted, could potentially be decoded by determined attackers, revealing authentication passwords and keys in their encrypted form. This scenario underscores the risk posed by the breach, particularly if attackers are able to crack or otherwise obtain the necessary decryption keys.
SonicWall and security vendors have issued urgent guidance to affected customers, recommending immediate review of the MySonicWall portal for impact assessment and the implementation of enhanced security measures. System administrators are advised to follow SonicWall’s security checklist, which includes steps such as resetting credentials, reviewing access logs, and applying any available patches or mitigations. The incident has prompted widespread concern within the security community due to the scale of the exposure and the potential for further exploitation.
The breach highlights the critical importance of strong encryption, robust credential management, and rapid incident response in cloud-based security services. It also demonstrates the potential for configuration data leaks to serve as a springboard for targeted attacks, including ransomware campaigns. Organizations using SonicWall products are urged to remain vigilant, monitor for signs of compromise, and coordinate closely with SonicWall and their security partners to mitigate ongoing risks. The incident serves as a stark reminder of the evolving threat landscape facing managed security service providers and their customers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting said a SonicWall cloud backup breach exposed customer network data or access, suggesting the impact extended beyond individual VPN account compromises. This appears to be an escalation in understanding of the scope affecting customers.
Attackers used previously stolen credentials in a broad campaign targeting SonicWall VPN accounts, leading to unauthorized access to customer environments. Reporting indicates the activity was widespread rather than limited to a single victim.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.